package com.founder.shiro;

import javax.servlet.ServletRequest;
import javax.servlet.ServletResponse;

import org.apache.shiro.authc.UsernamePasswordToken;
import org.apache.shiro.web.filter.authc.FormAuthenticationFilter;

public class MyFormAuthenticationFilter extends FormAuthenticationFilter {
	protected boolean onAccessDenied(ServletRequest request,
			ServletResponse response, Object mappedValue) throws Exception {
		 String username = getUsername(request);  
	        String password = getPassword(request);  
	        if (password == null) {  
	            password = "";  
	        }  
	    	return super.onAccessDenied(request, response, mappedValue);
	}
}
